
WPSniper
CVE-2026-87902 detector. WordPress get_page_template LFI class. Detect-only. Authorized lab.

CVE-2026-87902 detector. WordPress get_page_template LFI class. Detect-only. Authorized lab.
Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

Reflected XSS via search GET Parameter in Phoca Download

Python test client that sends HTTP GET requests with oversized Authorization headers to trigger header-parsing bugs like CVE-2025-4476. For…

Springboot web application accepts a name get parameter and logs its value to log4j2. Vulnerable to CVE-2021-44228.

Analyzes CVE-2021-42948, a session token exposure vulnerability in HotelDruid, demonstrating how GET parameters leak session IDs and enable session…

Proof-of-concept exploit for SQL injection in CodeAstro Online Job Portal allowing authenticated deletion of all job records via crafted GET request.

Proof-of-concept exploit for an unauthenticated IDOR vulnerability in FreeScout that allows thread enumeration and manipulation of read status via…

CVE on FlagForgeCTF on versions v2.0.0 to v2.3.1. Upgraded to version 2.3.2 to fix the issue.

Detection-only PoC for CVE-2026-21440 in AdonisJS BodyParser. Fingerprints AdonisJS indicators, probes upload endpoints via GET, and outputs…

Reflected XSS via price_from & price_to Filter Parameters in PhocaCart

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3

Here you will get awesome collection of mostly all well-known and usefull cybersecurity books from beginner level to expert for all cybersecurity…

Detects time-based SQL injection by sending crafted GET requests to multiple URLs and measuring delayed responses; includes cookie support for…

Subdomain takeover vulnerability checker

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

DDoS script meant to flood websites.

Enemies Of Symfony - Debug mode Symfony looter